Triple-A Updates

Triple-A Security Incident: Post-Mortem

August 21, 2026
8 mins

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

On 25 July 2026, Triple-A identified unauthorized access to certain operational wallets containing the company’s own digital assets. The incident was contained within approximately three hours. Every client transaction and settlement continued as normal across every market.

Security breaches are nothing new to the fintech and payments industries. As is often the case, this attack did not come through a flaw in a smart contract or a failure of infrastructure, but rather through social engineering. 

Yet, the design of how Triple-A operates, holds, and manages assets ensured that the attacker was unable to reach client funds. The loss was limited to treasury assets that Triple-A uses for our own conversions and it has been fully absorbed by our reserves.

Below, we walk through exactly what happened, how the attack unfolded, why client funds sat entirely outside the blast radius, and the security measures we've launched in response. 

TL;DR

  • On 25 July 2026, an attacker gained unauthorized access to certain operational wallets of Triple-A’s Singapore entity, which hold our own digital assets across TRON, Ethereum, Polygon, and Arbitrum.
  • Client funds were not affected. Triple-A's Singapore entity does not custody digital assets for clients. Client funds are held separately in trust accounts with safeguarding institutions including DBS and Standard Chartered, which were never exposed.
  • No other Triple-A regulated entities, licences, or regional operations were affected.
  • The attack began with social engineering, followed by privilege escalation and malicious code to move assets. It was not a flaw in Triple-A's products or infrastructure.
  • All services were restored within approximately three hours of detection and continue to operate normally across all markets.
  • The investigation is ongoing with forensic specialists Sygnia and blockchain-tracing firm zeroShadow, alongside the Monetary Authority of Singapore (MAS) and the Singapore Police Force.

Timeline of events

25 July 2026, approximately 2:39 AM GMT:
Triple-A identified unauthorized access to certain wallets operated by its Singapore entity and containing the company’s own digital assets.

25 July 2026, immediately after the attack:
Triple-A activated its incident response procedures, formed an incident committee and engaged external cybersecurity and blockchain forensics specialists. Certain services were placed in maintenance mode while security checks were completed. MAS and the Singapore Police Force were notified.

25 July 2026, approximately 5:15 AM
Following containment and initial verification, services were restored. Transactions and settlements resumed normally across all markets.

25–27 July 2026
Triple-A confirmed that client funds, transactions, and settlements were unaffected. Merchants and key partners were informed directly, followed by public updates and merchant communications on 27 July.

From 25 July 2026 to date
Sygnia and zeroShadow, two reputed cybersecurity expert firms, have been engaged to support the forensic investigation, asset tracing, and recovery. Additional safeguards, access controls, and monitoring are being implemented in parallel.

How the attack happened

The attackers used advanced social engineering techniques to compromise credentials associated with a member of Triple-A’s engineering team. 

Social engineering is often perceived as an oddly-formatted email with a phishing link. However, in this case, it was a multi-step attack that included communications across different channels, impersonation, and a live call. 

The attacker then gained unauthorized access to an operational environment and obtained higher-level system permissions. Following the initial compromise, the attacker deployed additional malware, accessed production databases, abused legitimate API credentials, and executed unauthorized cryptocurrency withdrawals. 

The attack was targeted and meticulously prepared. This once again highlights the importance of continuous employee training and threat awareness, since employees are the last line of defense for any company. 

Why client funds were not at risk

Client funds were not in the path of this attack because of how Triple-A is built. For the attacker, a route to access these funds simply did not exist.

The wallets involved in this incident were operational wallets belonging to Triple-A Technologies Pte. Ltd., our Singapore entity. They hold only Triple-A's own digital assets. Triple-A Singapore does not provide custodial services for digital assets.

Customer funds are deliberately kept in an entirely different structure. They are held in segregated trust accounts with established safeguarding institutions, including DBS and Standard Chartered, at regulated banks. They are kept separate from the company’s own funds and are not reachable from the operational environment the attacker compromised.

No other Triple-A regulated entities or regional operations were affected. Services were restored across all markets and have operated normally since. Triple-A remains well capitalized and continues to meet all of its liabilities in full.

Despite this, we do not treat this incident lightly. The response and remediation have been managed with the seriousness they deserve.  

Our response and security improvements 

When the unauthorized access was identified, Triple-A activated established incident response procedures, convened a dedicated incident committee, and placed affected services into maintenance mode while the environment was verified.

MAS and the Singapore Police Force were notified immediately. Forensic and blockchain-tracing specialists were engaged within hours. Sygnia led the forensic investigation and strengthened security controls, and zeroShadow was engaged to trace the affected assets and support recovery efforts.

Following the containment of the incident, a broader security improvement program was implemented and is being rolled out in phases under the guidance of external cybersecurity professionals. 

These are the steps we are taking to reduce the possibility of another attack: 

  • Reducing access to production systems, tightening approval and authentication requirements for sensitive wallet activity, and rotating and restricting credentials and access tokens
  • Increasing the separation between our corporate, production, and operational wallet environments so that access to one does not open a path to the others
  • Expanding logging, anomaly detection, real-time monitoring, and alert systems, with additional controls to flag credential misuse or attempted re-entry
  • Reviewing wallet exposure limits and the controls governing how and when assets can move
  • Strengthening emergency containment and recovery procedures, and commissioning independent security testing and validation

Threat landscape: Lessons for the industry

The attack on Triple-A was patient, multi-channel, and convincing enough to exploit trust through social engineering.

The threat came as a coordinated effort to impersonate, build credibility, and manipulate a single moment of human judgment. This is part of the system that is hardest to patch: the people who operate it.

For the industry, we believe that any organization, however well defended, must operate on the assumption that a determined attacker will eventually breach those defenses. What separates a contained incident from a catastrophic one is what the attacker is able to reach once they do manage to get in.

Triple-A intends to openly share what we learn from this incident with other companies where doing so will help others strengthen their own defenses. The security of any one participant contributes to trust in the system as a whole.

Ongoing investigation and what’s next

The investigation is ongoing. It is being conducted together with Sygnia, zeroShadow, and the Singapore Police Force, and in continued coordination with MAS.

It has already established a detailed understanding of the incident, including how the initial compromise occurred, the sequence of the attacker's activity, the scope of what was accessed, and the steps needed to secure the environment. 

Immediate containment is complete: active attacker access has been removed and the persistence mechanisms identified during the investigation have been eliminated.

The focus has now shifted to tracing the movement of the affected assets and to potential freezing and recovery actions. Tracing and recovering stolen digital assets is difficult and often slow, and we will not overstate the likelihood of return. However, the effort is active and ongoing.

From a business and product standpoint, Triple-A continues to meet all of its liabilities in full and is operating at normal service levels across all markets. 

In this article
Share